350-701 · Question #460
What is a function of the Layer 4 Traffic Monitor on a Cisco WSA?
The correct answer is C. monitors suspicious traffic across all the TCP/UDP ports. The Cisco WSA's Layer 4 Traffic Monitor provides comprehensive monitoring of suspicious traffic across all TCP/UDP ports, extending visibility beyond standard HTTP/HTTPS.
Question
What is a function of the Layer 4 Traffic Monitor on a Cisco WSA?
Options
- Ablocks traffic from URL categories that are known to contain malicious content
- Bdecrypts SSL traffic to monitor for malicious content
- Cmonitors suspicious traffic across all the TCP/UDP ports
- Dprevents data exfiltration by searching all the network traffic for specified sensitive information
How the community answered
(48 responses)- A2% (1)
- C92% (44)
- D6% (3)
Why each option
The Cisco WSA's Layer 4 Traffic Monitor provides comprehensive monitoring of suspicious traffic across all TCP/UDP ports, extending visibility beyond standard HTTP/HTTPS.
Blocking traffic from malicious URL categories is a function of URL filtering, which is separate from the Layer 4 Traffic Monitor's primary role.
Decrypting SSL traffic to monitor for malicious content is a function of SSL decryption (HTTPS inspection), which operates at a higher application layer.
The Layer 4 Traffic Monitor on a Cisco Web Security Appliance (WSA) is designed to monitor non-web (non-HTTP/HTTPS) traffic across all TCP and UDP ports. It identifies suspicious or anomalous activity by looking at connection characteristics, helping to detect malware communicating on non-standard ports or command-and-control channels.
Preventing data exfiltration by searching for sensitive information is a function of Data Loss Prevention (DLP), not the primary role of the Layer 4 Traffic Monitor.
Concept tested: Cisco WSA Layer 4 Traffic Monitor function
Source: https://www.cisco.com/c/en/us/td/docs/security/wsa/wsa11-7/user_guide/b_WSA_Admin_Guide_11_7/b_WSA_Admin_Guide_11_7_chapter_01000.html
Topics
Community Discussion
No community discussion yet for this question.